CVE-2025-12562: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12562?
CVE-2025-12562 is classified as a medium severity vulnerability.
How do I fix CVE-2025-12562?
To fix CVE-2025-12562, upgrade to GitLab versions 18.4.6, 18.5.4, or 18.6.2.
What types of attacks does CVE-2025-12562 enable?
CVE-2025-12562 allows unauthenticated users to perform denial of service attacks via crafted GraphQL queries.
Which versions of GitLab are affected by CVE-2025-12562?
GitLab versions from 11.10 up to but not including 18.4.6, 18.5 up to but not including 18.5.4, and 18.6 up to but not including 18.6.2 are affected by CVE-2025-12562.
Is authentication required to exploit CVE-2025-12562?
No, CVE-2025-12562 can be exploited by unauthenticated users.